Privacy Policy
As of: May 2026
1 Controller
The controller within the meaning of the General Data Protection Regulation ("GDPR") is:
Constantin Hirt
Gasborn 23
52062 Aachen, Germany
Email: hello@tusentakk.app
2 Scope
This Privacy Policy applies to the mobile application "Tusen Takk" (iOS, and potentially Android) and the website tusentakk.app.
3 What data we process
3.1 Account and profile data
During registration and use, we process the following data:
- Name (display name in the app);
- Email address;
- Password as a bcrypt hash (salt rounds: 10) — the plaintext password is never stored;
- Registration timestamp;
- PayPal.Me username (if stored by the User in their profile);
- Profile photo / avatar (if uploaded).
3.2 Transaction and activity data
- Sent and received Gift Tokens (gift type, amount in cents, status, timestamps);
- Occasion texts and notes optionally entered when sending;
- Selfies and captions uploaded for redemption;
- Approval/rejection decisions and timestamps;
- Chat entries (comments, reactions, photos) in the gift history;
- Points events ("Social Score"), weekly challenges, achievements, friendship connections;
- For unregistered recipients: their email address as a pending gift entry, until registration or for a maximum of 90 days.
3.3 Device and technical data
- Authentication token (JWT, validity 30 days, stored locally on the device);
- Push notification token (Expo Push Service), if the User has enabled push notifications;
- Server log data (timestamp, IP address, user agent, accessed endpoints) to ensure functionality and ward off attacks.
4 Purposes and legal bases for processing
| Purpose | Legal basis |
| Provision of the app, authentication and account management | Art. 6(1)(b) GDPR (performance of contract) |
| Processing of gift transactions including redemption and payout | Art. 6(1)(b) GDPR |
| Display of selfies to the Sender for approval | Art. 6(1)(b) GDPR; where applicable Art. 9(2)(a) GDPR (consent), see section 6 |
| Push notifications | Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR |
| Points, levels and leaderboard function | Art. 6(1)(b) GDPR |
| Server logs for IT security | Art. 6(1)(f) GDPR (legitimate interest) |
| Compliance with legal obligations (e.g. information and retention obligations) | Art. 6(1)(c) GDPR |
5 Recipients and processors
We share personal data with recipients only where this is necessary for the provision of the service or a legal obligation exists. The following processors and independent recipients are used:
- PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg — processing of payouts via PayPal.Me. Only the PayPal.Me username and the payout amount are transmitted.
- Expo (650 Industries, Inc.), USA — provision of the push notification service. Data transfer to the USA on the basis of EU Standard Contractual Clauses.
- Replit, Inc., USA — hosting and operation of the backend servers (Express) and the app infrastructure. Data transfer to the USA on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR (EU Standard Contractual Clauses / EU–US Data Privacy Framework).
- Apple Inc. — distribution of the app via the App Store; technical telemetry data is transmitted in accordance with Apple's guidelines.
Transfer of data to third countries outside the EU/EEA takes place only on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR.
6 Processing of the Redemption Selfie
To evidence that a Recipient has actually redeemed the gift assigned to them, the Recipient uploads a photo (typically a selfie with the gift) during the redemption process. This photo is shown exclusively to the Sender of the gift for confirmation.
Purpose of processing: Evidence of actual redemption to enable the Sender to release the payment.
Legal basis: Art. 6(1)(b) GDPR (execution of the user-initiated redemption process) as well as Art. 6(1)(a) GDPR (consent through deliberate upload). To the extent that a selfie contains facial features that may in individual cases be classified as biometric data within the meaning of Art. 9 GDPR, the processing is additionally based on explicit consent pursuant to Art. 9(2)(a) GDPR.
Retention period: The photo is automatically deleted from our systems 30 days after the final confirmation by the Sender. If the Sender does not confirm the redemption, deletion occurs 30 days after upload. The Recipient may delete the photo at any earlier time.
Data recipients: The photo is shown exclusively to the Sender of the respective gift. No automated facial recognition, no biometric matching, and no disclosure to third parties takes place.
Withdrawal and deletion: The Recipient may withdraw consent at any time and request immediate deletion of the photo, without any reason being required. Contact: hello@tusentakk.app.
7 Storage periods
- Account and profile data: until account deletion.
- Transaction data: until account deletion, then anonymisation; statutory retention periods remain unaffected.
- Redemption selfies: automatic deletion 30 days after final confirmation by the Sender or 30 days after upload if no confirmation occurs (see Section 6). Chat content: until deleted by the User or upon account deletion, at the latest 30 days after account deletion.
- Pending gifts (email addresses of unregistered recipients): automatic deletion after 90 days without claim.
- Server logs: max. 30 days.
- Push tokens: until withdrawal of push consent or account deletion.
8 Your rights
You have the right at any time to:
- Access to data stored about you (Art. 15 GDPR);
- Rectification of inaccurate data (Art. 16 GDPR);
- Erasure (Art. 17 GDPR);
- Restriction of processing (Art. 18 GDPR);
- Data portability (Art. 20 GDPR);
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR);
- Withdrawal of consent with future effect (Art. 7(3) GDPR);
- Lodge a complaint with a supervisory authority (Art. 77 GDPR).
To exercise your rights, a simple message to hello@tusentakk.app or use of the "Delete account" function in the app (Profile → Settings) is sufficient.
9 Security
- All data transmission exclusively encrypted via HTTPS/TLS;
- Passwords are hashed with bcrypt and not stored in plaintext;
- Authentication via JWT tokens with limited validity;
- Database access is only possible for authorised services and persons;
- Rate limiting on sensitive endpoints (login, signup, coin send, avatar upload);
- Regular updates of components in use.
10 Automated decisions and profiling
No exclusively automated decision-making within the meaning of Art. 22 GDPR takes place. The approval of a selfie is always carried out manually by the Sender. Points are awarded according to fixed rules and do not lead to legal or comparably significant effects.
11 Changes to this Privacy Policy
We reserve the right to update this Privacy Policy when app functions change or the legal situation requires it. Material changes will be communicated via the app or by email.
12 Data protection contact
For questions about data protection or to exercise your rights, please contact us at:
Constantin Hirt — Data Protection
Gasborn 23
52062 Aachen
Email: hello@tusentakk.app